Symantec Blogs: Security ResponseSyndicate content

Ben Greenbaum | July 9th, 2007
0 comments

This month's Microsoft patch releaseincludes six bulletins, addressing 12 vulnerabilities in common clientand server software, including four in a popular developmentenvironment. Topping the heap in terms of urgency is a remotelyexploitable, server side code execution vulnerability in IIS, andthat's where we'll start:

MS07-041;KB939373Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution

This bulletin addresses a previously known issue in IIS 5.1 onWindows XP that was reported in late 2005 as a denial-of-serviceproblem. It is now known to be exploitable to run attacker code. IIS isnot running or installed by default on Windows XP.

  • Microsoft Internet Information Server 5.1 DLL Request Remote Code Execution Vulnerability
    BID...